CVE-2017-7320: Modx Revolution
Medium severity, CVSS 6.1. EPSS: 0.9% chance of exploitation in the next 30 days.
setup/controllers/language.php in MODX Revolution 2.5.4-pl and earlier does not properly constrain the language parameter, which allows remote attackers to conduct Cookie-Bombing attacks and cause a denial of service (cookie quota exhaustion), or conduct HTTP Response Splitting attacks with resultant XSS, via an invalid parameter value.
Affected products
- Modx Modx Revolution: up to and including 2.5.4
Published 2017-03-30. Last modified 2026-06-17.